Pixel 10에서 C2PA 출처 정보 위조 공격이 시연됨.
Pixel 10에서 실제 카메라의 C2PA 서명을 위조하지 않고, 기기의 서명 기능으로 가짜 출처 정보를 인증하는 공격 방법이 시연되었습니다. 이 공격은 기기 초기화 없이 루트 권한을 확보해야 하며, StrongBox에서 키를 추출하는 것이 포함됩니다. 이로 인해 AI로 생성된 이미지의 출처 정보가 조작될 수 있는 위험성이 제기되고 있습니다.
Demo shows attack to forge C2PA source info on Pixel 10.
An attack was demonstrated on the Pixel 10 that forges C2PA source info using the device's signature feature to authenticate fake camera source information without tampering with the actual camera's signature. This attack requires root access obtained without factory resetting the device and involves extracting keys from StrongBox. This poses a risk of manipulation in source information for AI-generated images.